Liferay DXP Vulnerability - CVE-2021-38266 - Vulnerability Database

Liferay DXP Vulnerability - CVE-2021-38266

High
Reference: CVE-2021-38266
Title: Liferay DXP Vulnerability
Overview:

Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.